Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-2226

Опубликовано: 15 июл. 2020
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.

A flaw was found in the Matrix Authorization Strategy Plugin version 2.6.1 and prior. User names are not escaped in the permission table which could lead to a stored cross-site scripting (XSS) vulnerability. The user must have the Agent/Configure, Job/Configure, or Overall/Administer permissions for this exploit to function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1857441jenkins-2-plugins/matrix-auth: Stored XSS vulnerability in Matrix Authorization Strategy Plugin

EPSS

Процентиль: 58%
0.00919
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 6 лет назад

Jenkins Matrix Authorization Strategy Plugin 2.6.1 and earlier does not escape user names shown in the configuration, resulting in a stored cross-site scripting vulnerability.

CVSS3: 8
github
больше 4 лет назад

Stored XSS vulnerability in Jenkins Matrix Authorization Strategy Plugin

EPSS

Процентиль: 58%
0.00919
Низкий

8 High

CVSS3